WordPress Gallery plugin before 2.0.0 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back in the response of an AJAX action, available to both unauthenticated and authenticated users.
id: CVE-2022-1946
info:
name: WordPress Gallery <2.0.0 - Cross-Site Scripting
author: Akincibor
...